LEGAL

Privacy Policy

How we collect, process, and protect personal data under the GDPR.

Effective:July 27, 2026Jurisdiction:EEA (Czech Republic & Slovakia)

1. Introduction and Operator Identity

This Privacy Policy governs the collection, processing, and protection of personal data by the GainSync platform, including its web and mobile applications, APIs, and related services (collectively, the "Service").

The Service is operated by [Your Full Name], an independent entrepreneur (OSVČ) registered under IČO: [Insert IČO], with a registered office at [Insert Address], Czech Republic ("GainSync", "we", "us", or "our"). We strictly adhere to the General Data Protection Regulation (EU) 2016/679 ("GDPR").

3. Data Inventory: What We Collect

We apply strict data minimization.

3.1 Data Collected from Coaches (Controller Context)

Account Data: Full name, business email address, and cryptographically hashed passwords.

Financial Data: Subscription status, billing history, and tax identification numbers. GainSync does not process, transmit, or store raw credit card data. All financial transactions are executed strictly via our Merchant of Record, Paddle.

3.2 Data Processed on Behalf of Coaches (Processor Context)

Client Profile Data: Names, email addresses, and platform identifiers.

Health and Biometric Data: Workout logs, body weight, measurements, injury disclosures, nutritional data, and performance metrics.

3.3 System and Diagnostic Data

IP addresses, device identifiers, operating systems, and crash logs utilized strictly for platform diagnostics and security incident response.

4. Lawful Basis for Processing (GDPR)

Contractual Necessity (Art. 6(1)(b)): To provision the Service, authenticate users, and enforce our Terms of Service.

Legitimate Interests (Art. 6(1)(f)): To monitor security, prevent fraud, and optimize system performance.

Explicit Consent (Art. 9(2)(a)): Processing Client biometric and fitness metrics requires explicit, affirmative consent. Clients grant this consent directly to their Coach. Clients may withdraw this consent at any time, compelling the immediate cessation of processing and deletion of the applicable health data.

5. Sub-Processors and Data Disclosure

We utilize vetted Sub-processors bound by strict confidentiality agreements. Data is shared exclusively for operational execution:

Infrastructure

Secure cloud hosting, database management, and email delivery services.

Merchant of Record

Paddle, for subscription billing and tax remittance.

Legal Compliance

We will disclose data only if legally compelled by a binding subpoena or court order from competent authorities within our jurisdiction.

6. Commercial Rights to Anonymized Data

GainSync reserves the right to aggregate, de-identify, and anonymize data collected through the Service so that it can no longer be linked to any individual person or entity. Once anonymized, this data ceases to be Personal Data under the GDPR. We claim full ownership of this anonymized data and may use it for any commercial purpose, including but not limited to platform benchmarking, machine learning model training, and public analytics.

7. Cookies and Authentication

We utilize essential local storage mechanisms (such as JWT tokens) strictly necessary for user authentication, API authorization, and session security. As these are fundamentally required for the Service to function, they are exempt from prior-consent requirements under the ePrivacy Directive. We deploy zero third-party advertising or tracking cookies.

8. Age Restriction (Minors)

The Service is strictly intended for individuals aged 16 and older. We do not knowingly collect personal data from anyone under the age of 16. If we discover that a user under 16 has provided personal data without verifiable parental consent, we will immediately and permanently terminate the account and purge all associated data.

9. Data Security and User Responsibility

We enforce industry-standard security protocols, including TLS 1.2+ encryption in transit and AES encryption at rest. However, no internet-based system is entirely impenetrable. You acknowledge that you transmit data to the Service at your own risk. Furthermore, you are solely responsible for maintaining the confidentiality of your account credentials. GainSync is not liable for data breaches resulting from compromised user passwords or unauthorized device access.

10. Data Retention

Coach account data is retained for the duration of an active subscription. Upon account termination, all associated Personal Information and Client Health Data are irreversibly permanently purged within 30 days, excluding minimal billing records retained solely to satisfy statutory tax obligations.

11. Your Data Subject Rights (GDPR)

You possess the right to access, rectify, restrict processing, or request the erasure of your data, and the right to data portability. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ).

Coaches

Execute these rights via your Account Settings or by emailing [Insert Support Email].

Clients

Because your Coach is the Data Controller, you must route all GDPR requests directly to your Coach. GainSync will execute the technical deletion of your data only upon receiving instructions from your Coach.

12. Policy Modifications

We reserve the right to unilaterally modify this Privacy Policy to reflect changes in legal or operational requirements. Material changes will be communicated via the Service. Continued use of the Service following such updates constitutes binding acceptance of the revised policy.

← Back to home